OrangeScrum 2.0.11 - AWS Credentials Leak
6,5
Medium
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
OrangeScrum 2.0.11 - AWS Credentials Leak
Code name
State
Public
Release date
23 jun 2023
Affected product
OrangeScrum
Affected version(s)
Version 2.0.11
Vulnerability name
Server Side XSS
Vulnerability type
Remotely exploitable
Yes
CVSS v3.1 vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1 base score
6.5
Exploit available
Yes
CVE ID(s)
Description
OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.
Vulnerability
This vulnerability occurs because the application does not properly validate the HTML content to be converted to PDF.
Exploitation


Our security policy
We have reserved the CVE-2023-1783 to refer to these issues from now on. Disclosure policy
System Information
Version: OrangeScrum 2.0.11
Operating System: GNU/Linux
Mitigation
There is currently no patch available for this vulnerability.
References
Vendor page https://github.com/Orangescrum/orangescrum/
Timeline
IA generativa
31 mar 2023
Vendor contacted
31 mar 2023
Vendor replied
31 mar 2023
Public disclosure
23 jun 2023